CVE-2023-0217
Last modified
CVE-2023-0217 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. EPSS estimates a 1.85% chance of exploitation in the next 30 days.
Description
An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted sources which could allow an attacker to cause a denial of service attack. The TLS implementation in OpenSSL does not call this function but applications might call the function if there are additional security requirements imposed by standards such as FIPS 140-3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | >= 3.0.0, <= 3.0.7 |
References
- https://www.openssl.org/news/secadv/20230207.txtVendor Advisory
- https://www.openssl.org/news/secadv/20230207.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-0217?
How severe is CVE-2023-0217?
How do I fix CVE-2023-0217?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-0210A bug affects the Linux kernel’s ksmbd NTLMv2 authentication…7.5
- CVE-2023-0212The Advanced Recent Posts WordPress plugin through 0.6.14 do…5.4
- CVE-2023-0213Elevation of privilege issue in M-Files Installer versions b…7.8
- CVE-2023-0214A cross-site scripting vulnerability in Skyhigh SWG in main …6.1
- CVE-2023-0215The public API function BIO_new_NDEF is a helper function us…7.5
- CVE-2023-0216An invalid pointer dereference on read can be triggered when…7.5
- CVE-2023-0219The FluentSMTP WordPress plugin before 2.2.3 does not saniti…5.4
- CVE-2023-0220The Pinpoint Booking System WordPress plugin before 2.9.9.2.…8.8
- CVE-2023-0221Product security bypass vulnerability in ACC prior to versio…4.4
- CVE-2023-0223An issue has been discovered in GitLab affecting all version…5.3
- CVE-2023-0224The GiveWP WordPress plugin before 2.24.1 does not properly …9.8
- CVE-2023-0225A flaw was found in Samba. An incomplete access check on dns…4.3
Are you affected by CVE-2023-0217?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
